Missing authorization check in SAP NetWeaver AS ABAP exposes system configuration data
AI analysis
CVE-2026-76963 is a missing authorization check (CWE-862) in Application Server ABAP of SAP NetWeaver and ABAP Platform. A low-privileged authenticated user with network access to the affected system can trigger the flaw and gain unauthorized access to sensitive system configuration information, including security-relevant settings and internal system details. The impact is limited to confidentiality (CVSS 4.3 medium); integrity and availability are unaffected. Any organization running SAP NetWeaver AS ABAP or ABAP Platform is potentially affected. As of this analysis there is no known public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation within 30 days.
What to do: Apply the corrective patch released by SAP in its September 2026 Security Patch Day for NetWeaver AS ABAP / ABAP Platform, consulting the SAP advisory for the exact versions covered. Until patched, restrict which low-privileged authenticated users can access the affected Application Server ABAP services and review roles/authorizations for over-provisioning. Check logs for unusual authenticated reads of configuration data by low-privilege users.
Affected
| SAP NetWeaver Application Server ABAP | — |
| SAP ABAP Platform | — |
Estimated exposure
largeon the order of 10,000-100,000 ABAP-based SAP system installations worldwide (exact count unknown) — SAP Application Server ABAP is the runtime for widely deployed SAP ERP/S4HANA landscapes across SAP's large enterprise customer base, and while many of these systems are internal rather than internet-exposed, the deployed population…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected.